Re: [strongSwan] traffic shaping on tunnels

2009-08-20 Thread Martin Kellermann
no one? hi list, setup is strongswan 4.1.11 running on a linux box with kernel 2.6.24.3 since the not ipsec-related traffic gets higher on this box, i wanted to know which is the easiest way to do some traffic shaping like reserve x mbit for tunnel A, y mbit for tunnel B etc. and let re

Re: [strongSwan] anti-replay window size?

2009-08-20 Thread Andreas Steffen
Hello, currently the kernel interface method add_sa() of the IKEv2 daemon sets the replay window size to a constant value of 32: http://wiki.strongswan.org/repositories/entry/strongswan/src/charon/plugins/kernel_netlink/kernel_netlink_ipsec.c#L965 whereas in the kernel interface method

Re: [strongSwan] unable to allocate SPIs from kernel

2009-08-20 Thread Deva Pandian
Can someone please help me with this unable to allocate SPIs from kernel message? On Tue, Aug 18, 2009 at 3:34 PM, Deva Pandiandeva.pand...@gmail.com wrote: Hi,  I am an ipsec beginner.  I installed strongswan 4.3.3 on my FC10/FC11 machines and tried to setup a host-host tunnel.  But I get the